Crack

About “Win32/HackKMS.Z potentially unsafe” infection

Malware Removal

The Win32/HackKMS.Z potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/HackKMS.Z potentially unsafe virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/HackKMS.Z potentially unsafe?


File Info:

crc32: E7A5E060
md5: bd6b24734d0f426b5f4aa9d2a2ba323c
name: BD6B24734D0F426B5F4AA9D2A2BA323C.mlw
sha1: 777a22e7734e1901f369f5a6db5d28324b71e5fa
sha256: aeaac9e5b5fb3aa355a9ce8b961834e039e7d5cd45fc1f1637c1eedd9f4dd85b
sha512: f847ccb1a49b2d0ed508546ec4c067c40f203c8499d37eda03b2fe56a57924913a3ad48e15890cfd7876ad21d0134e9679104b308146f0cbdc9652fb6289f8af
ssdeep: 24576:miQsFhBhmAWAdnQxlfj6Ya+GNAELR5iJb/Xf8+ROvXfYSS:4sFlmAWAdQTfj6Ya+GNAELRc58oOoSS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright(C) 2012-2013 By Zbezj
CompanyName: HEU CNST
FileVersion: 1.0.0.1
Comments: x672cx5730KMSx6fc0x6d3bxff0cx65e0x9700x8054x7f51
FileDescription: HEU KMS Renewal
Translation: 0x0804 0x04b0

Win32/HackKMS.Z potentially unsafe also known as:

McAfeeArtemis!BD6B24734D0F
K7AntiVirusUnwanted-Program ( 004d99691 )
K7GWUnwanted-Program ( 004d99691 )
TrendMicroTROJ_GEN.R00UC0VFN16
BaiduWin32.Trojan.WisdomEyes.151026.9950.9995
CyrenW32/Trojan.IJBN-1595
SymantecHeur.AdvML.B
ESET-NOD32a variant of Win32/HackKMS.Z potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R00UC0VFN16
ClamAVWin.Trojan.8468349-1
NANO-AntivirusTrojan.Win32.Kryptik.dytosd
ViRobotTrojan.Win32.A.Agent.690283[h]
ComodoTrojWare.Win32.Hider.REXR
VIPRETrojan.Win32.Generic!BT
Invinceaworm.win32.jenxcus.a
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
SophosGeneric PUA HH (PUA)
F-ProtW32/Trojan2.NVGH
Antiy-AVLGrayWare[AdWare]/Win32.Phorpiex.c
AegisLabW32.Riskware.Hackkms!c
GDataWin32.Riskware.HackKMS.L
AhnLab-V3Unwanted/Win32.KMS.R164077
VBA32IMWorm.Sohanad
AVwareTrojan.Win32.Generic!BT
IkarusTrojan.Patched2
FortinetRiskware/HackKMS
AVGPatched2_c.CNIM

How to remove Win32/HackKMS.Z potentially unsafe?

Win32/HackKMS.Z potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment